Back to glossary

TIBER-EU

In the security of the European financial sector, TIBER-EU (Threat Intelligence-based Ethical Red Teaming) is the framework the European Central Bank published in 2018 so that authorities could commission intelligence-led red team exercises against critical live production systems. Its January 2025 revision aligned it with the DORA TLPT technical standards.

September 6, 2026
Share:

How it works

TIBER-EU stands for Threat Intelligence-based Ethical Red Teaming, the framework the European Central Bank published on 2 May 2018 so that European financial authorities could commission intelligence-led red team exercises through one common process. The approach came from TIBER-NL, which De Nederlandsche Bank developed in 2016. The framework defines the exercise as a controlled, bespoke, intelligence-led red team test of the entity’s critical live production systems. There is no laboratory environment, and that single decision shapes everything else.

The process has three phases, and the January 2025 version keeps all three. The preparation phase agrees the scope and stands up the team that governs the test. The testing phase splits in two: a threat intelligence provider produces the adversary profile and the scenarios, and the red team then executes them. The closure phase is not sending the report and leaving: it includes remediation planning and the sharing of results with the authority.

The allocation of roles is what separates this from an ordinary penetration test. Inside the entity only a small group knows what is happening: the Control Team, with its Control Team Lead, called the White Team until 2025. The blue team is not told, which is why its detection and response can be measured. The authority provides a TIBER Cyber Team with its test manager, the intelligence and red team providers are external, and the ECB hosts the TIBER-EU Knowledge Centre, where the national teams coordinate.

On whether it is compulsory, precision matters. What is voluntary is a jurisdiction’s adoption of the framework; participation by entities, the framework says, may be either voluntary or mandatory, at the discretion of the relevant national or European authorities. The January 2025 revision, announced on 11 February, aligned the framework with the DORA TLPT regulatory technical standards: it renamed the White Team, set strict delivery deadlines and made purple teaming mandatory.

What goes wrong

The first failure is one of reading, and it arrives before any technical decision: taking it as settled that TIBER-EU is voluntary and filing the matter away. In Spain, taking part in TIBER-ES is voluntary, but that says nothing about DORA, which obliges the entities identified by their competent authority to carry out threat-led testing at least every three years. The useful question is not whether the entity wants the exercise, but whether the authority has identified it.

The second is the calendar. The delegated regulation behind DORA TLPT requires the active red team phase to last at least twelve weeks, with reporting at least weekly to the control team and the test managers, and closure adds its own deadlines: four weeks for the red team report, up to ten for the blue team report and the joint replay, and eight from the authority’s notification for the summary report and the remediation plans. It occupies quarters, not weeks.

The third is arriving with nothing to measure. The exercise is not hunting isolated vulnerabilities: it observes what an unwarned defence detects and how it responds. With no detection engineering behind it, the report will say nobody saw anything, an expensive conclusion for something that could have been predicted for free.

The fourth is forgetting what it runs against. These are live production systems and genuinely critical functions, so deconfliction, the abort procedure and the authorisation chain are part of the design, not of the small print. The TIBER-ES implementation guide is equally blunt about the money: tests run against production environments, external third-party providers execute them, and all the costs and risks are borne entirely by the entity being tested.

TIBER-EU, DORA TLPT and TIBER-ES

Spanish financial entities reach this through three doors and often believe they are three programmes. It is the same exercise against production, seen from the method (TIBER-EU), from the legal obligation (DORA TLPT) and from the national implementation (TIBER-ES).

TIBER-EU DORA TLPT TIBER-ES
What it is ECB framework, published May 2018, revised January 2025 Obligation under Regulation (EU) 2022/2554, developed by Delegated Regulation (EU) 2025/1190 National implementation; the Banco de España took ownership in December 2020
Entity participation Voluntary or mandatory, as the authority decides Mandatory for identified entities, at least every three years Voluntary
Who executes Intelligence and red team providers, both external Testers under Article 27; intelligence always external; with internal testers, external ones every three tests External third-party providers
Role of the authority TIBER Cyber Team, with its test manager The authority’s TLPT team, mirroring the TIBER cyber teams TCT of Banco de España, CNMV and DGSFP, with no supervisory function
Fit with compliance Completing it leaves the entity DORA TLPT-compliant if the formal requirements are met Its technical standards were drafted in accordance with TIBER-EU and mirror its methodology One of those implementations; the TCT’s actions are not linked to the imposition of requirements where weaknesses are found

There is no framework to choose between. Recital 1 of the delegated regulation states that it was drafted in accordance with TIBER-EU and that entities subject to TLPT may apply the European framework or one of its national implementations, provided it is consistent with Articles 26 and 27 of DORA. The ECB publishes the list of jurisdictions that have adopted it, currently twenty, among them Spain and Germany, where the Bundesbank provides it and participation is voluntary. What changes from one to another is who you talk to, not the method.

Common mistakes

Repeating that TIBER-EU is voluntary without saying for whom. Adoption by a jurisdiction is voluntary; entity participation is the authority’s call, and DORA imposes it on the entities it identifies.

Planning the exercise as a penetration test of a few weeks. The active phase lasts at least twelve weeks under the delegated regulation, and closure adds its own deadlines on top.

Working from the 2018 framework as if it were current. The ECB revised it in January 2025 and the White Team became the Control Team; the old terminology produces pointless arguments.

Choosing providers before reading the requirements. The threat intelligence provider must be external to the entity, and anyone using internal testers has to contract external ones every three tests.

Treating purple teaming as a provider extra. The 2025 revision made it mandatory, so the replay with the defenders is part of the exercise and of its calendar.

How to prepare

Find out which door you come through before designing anything. Ask the competent authority whether the entity is identified for DORA TLPT rather than inferring it from size, because the calendar, the scope and who validates what all follow from that answer. If the route is TIBER-ES, the counterpart is a TCT with no supervisory function.

Stand up the control team before the exercise. Who leads it, who authorises the start, who can stop it at three in the morning and who speaks to the authority are decisions taken cold, because the group is deliberately small and every person added changes what is being measured.

Prepare the defence you are going to measure. The test measures detection and response, so the preparatory work is detection engineering and purple team exercises, not a stack of penetration test reports. The order that works is fix the obvious, build detection, and reach the exercise with something worth measuring.

Book the whole calendar and not only the active part: twelve weeks minimum, four for the red team report, up to ten for the blue team report and the replay, and eight from the authority’s notification for the summary and the remediation plans. Plan that remediation to survive the gap between tests, since three-year intervals are the norm, and settle the rules of engagement in writing.

Where this shows up in an audit

The evidence from a TIBER-EU exercise is not a report, it is a file: the agreed scope, the intelligence that shaped it, the rules of engagement, the red team report, the blue team report with timelines of what was detected and what was not, the replay with the defenders and the remediation plan. The DORA TLPT delegated regulation orders that same sequence in its articles, attestation included, so the file is either built while the work happens or reconstructed later from email, which is the expensive option.

We are explicit about what we contribute: we run the technical exercise and produce the evidence. We do not determine regulatory scope, we do not decide whether an entity is identified for TLPT, and we file nothing with any authority. Where the exercise has to be formally recognised, requirements on providers and on process apply, and they are worth confirming with the authority before any scoping.

Severity is written against the critical function affected rather than the technical asset, because that is the unit both the rules and the reader work in. An intelligence-led exercise against production and against a defence nobody warned is the adversary emulation we run end to end.

FAQ

Is TIBER-EU mandatory? It depends for whom. A jurisdiction’s adoption of the framework is voluntary, and entity participation may be either voluntary or mandatory at the authority’s discretion. In Spain, taking part in TIBER-ES is voluntary, but DORA does oblige the entities identified by their competent authority.

What is the difference between TIBER-EU and DORA TLPT? TIBER-EU is the method, published by the ECB in 2018 and revised in January 2025. DORA TLPT is the legal obligation, in Article 26 of Regulation (EU) 2022/2554 and in Delegated Regulation (EU) 2025/1190, whose technical standards were drafted in accordance with TIBER-EU.

How long does an exercise take? The active red team phase lasts at least twelve weeks under the delegated regulation, and closure adds four weeks for the red team report, up to ten for the blue team report and the joint replay, and eight from the authority’s notification for the summary and the remediation plans.

Does a TIBER-ES test satisfy DORA? The January 2025 framework states that entities completing a test under a national or European implementation of TIBER-EU will be DORA TLPT-compliant, assuming they fulfil the formal requirements set by their competent authorities. Those requirements are worth confirming with the authority first.

Want to see how we work at Asperis Security?

Book 30 minutes with one of our specialists. We look at your stack and tell you what is worth testing first.